
C
HAPTER
14
| Security Measures
IP Source Guard
– 351 –
C
OMMAND
U
SAGE
◆
Setting source guard mode to SIP (Source IP) or SIP-MAC (Source IP
and MAC) enables this function on the selected port. Use the SIP option
to check the VLAN ID, source IP address, and port number against all
entries in the binding table. Use the SIP-MAC option to check these
same parameters, plus the source MAC address. If no matching entry is
found, the packet is dropped.
N
OTE
:
Multicast addresses cannot be used by IP Source Guard.
◆
When enabled, traffic is filtered based upon dynamic entries learned via
), or static
addresses configured in the source guard binding table.
◆
If IP source guard is enabled, an inbound packet’s IP address (SIP
option) or both its IP address and corresponding MAC address (SIP-
MAC option) will be checked against the binding table. If no matching
entry is found, the packet will be dropped.
◆
Filtering rules are implemented as follows:
■
If DHCP snooping is disabled (see
), IP source guard will
check the VLAN ID, source IP address, port number, and source
MAC address (for the SIP-MAC option). If a matching entry is found
in the binding table and the entry type is static IP source guard
binding, the packet will be forwarded.
■
If DHCP snooping is enabled, IP source guard will check the VLAN
ID, source IP address, port number, and source MAC address (for
the SIP-MAC option). If a matching entry is found in the binding
table and the entry type is static IP source guard binding, or
dynamic DHCP snooping binding, the packet will be forwarded.
■
If IP source guard if enabled on an interface for which IP source
bindings have not yet been configured (neither by static
configuration in the IP source guard binding table nor dynamically
learned from DHCP snooping), the switch will drop all IP traffic on
that port, except for DHCP packets.
P
ARAMETERS
These parameters are displayed:
◆
Filter Type
– Configures the switch to filter inbound traffic based
source IP address, or source IP address and corresponding MAC
address. (Default: None)
■
None
– Disables IP source guard filtering on the port.
■
SIP
– Enables traffic filtering based on IP addresses stored in the
binding table.
Содержание ES3510MA-DC
Страница 1: ...Management Guide www edge core com 8 Port Layer 2 Fast Ethernet Switch...
Страница 2: ......
Страница 4: ......
Страница 6: ...ABOUT THIS GUIDE 6...
Страница 44: ...FIGURES 44...
Страница 50: ...TABLES 50...
Страница 52: ...SECTION I Getting Started 52...
Страница 62: ...CHAPTER 1 Introduction System Defaults 62...
Страница 80: ...CHAPTER 2 Initial Switch Configuration Managing System Files 80...
Страница 82: ...SECTION II Web Configuration 82...
Страница 98: ...CHAPTER 3 Using the Web Interface Navigating the Web Browser Interface 98...
Страница 126: ...CHAPTER 4 Basic Management Tasks Resetting the System 126...
Страница 164: ...CHAPTER 5 Interface Configuration VLAN Trunking 164 Figure 57 Configuring VLAN Trunking...
Страница 202: ...CHAPTER 7 Address Table Settings Configuring MAC Address Mirroring 202...
Страница 452: ...CHAPTER 17 IP Services Displaying the DNS Cache 452...
Страница 498: ...CHAPTER 19 Using the Command Line Interface CLI Command Groups 498...
Страница 588: ...CHAPTER 22 SNMP Commands 588...
Страница 596: ...CHAPTER 23 Remote Monitoring Commands 596...
Страница 650: ...CHAPTER 24 Authentication Commands Management IP Filter 650...
Страница 738: ...CHAPTER 27 Interface Commands 738...
Страница 760: ...CHAPTER 29 Port Mirroring Commands RSPAN Mirroring Commands 760...
Страница 782: ...CHAPTER 32 Address Table Commands 782...
Страница 810: ...CHAPTER 33 Spanning Tree Commands 810...
Страница 862: ...CHAPTER 35 VLAN Commands Configuring Voice VLANs 862...
Страница 876: ...CHAPTER 36 Class of Service Commands Priority Commands Layer 3 and 4 876...
Страница 932: ...CHAPTER 38 Multicast Filtering Commands Multicast VLAN Registration 932...
Страница 956: ...CHAPTER 39 LLDP Commands 956...
Страница 1020: ...CHAPTER 42 Domain Name Service Commands 1020...
Страница 1026: ...CHAPTER 43 DHCP Commands DHCP Client 1026...
Страница 1058: ...CHAPTER 44 IP Interface Commands IPv6 Interface 1058...
Страница 1060: ...SECTION IV Appendices 1060...
Страница 1065: ...APPENDIX A Software Specifications Management Information Bases 1065 Trap RFC 1215 UDP MIB RFC 2013...
Страница 1066: ...APPENDIX A Software Specifications Management Information Bases 1066...
Страница 1088: ...COMMAND LIST 1088...
Страница 1097: ......
Страница 1098: ...ES3510MA DC E122010 ST R01 150200000251A...